Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2554 | Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0. |
Github GHSA |
GHSA-c6c3-h4f7-3962 | apollo-portal has potential unauthorized access issue |
Mon, 26 Aug 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apolloconfig
Apolloconfig apollo |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:apolloconfig:apollo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apolloconfig
Apolloconfig apollo |
Tue, 20 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0. | |
| Title | Potential unauthorized access issue in apollo-portal | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-20T17:18:53.095Z
Reserved: 2024-08-12T18:02:04.965Z
Link: CVE-2024-43397
Updated: 2024-08-20T17:18:40.540Z
Status : Analyzed
Published: 2024-08-20T15:15:23.673
Modified: 2024-08-26T18:28:42.230
Link: CVE-2024-43397
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA